Educause Security Discussion mailing list archives

Re: Password Expatriation notification


From: Russell Fulton <r.fulton () AUCKLAND AC NZ>
Date: Sat, 21 Aug 2010 17:35:40 +1200

On 18/08/2010, at 6:44 AM, James Farr '05 wrote:

We recently implemented a policy where the users receives an email 30 days
before the password is set to expire.   Sure enough people thought this was
a phishing attempt.   However, since we have some off campus users that may
never step foot on campus email seemed to be the only way to notify
everyone.



I have had this problem notifying people about possibly compromised credentials too.

After a bit of toing and froing we managed to convince the keepers of the university home page to add a password change 
link to the list of quick links on www.auckland.ac.nz.   Now we can tell folk how to change password easily without 
giving any urls.  We will use the same technique when we start expiring passwords later this year.

Russell


Current thread: